Friday , November 22 2024
Ransomware landscape

BGD e-GOV CIRT Report
Bangladesh faced 71.39% of Malware Infections Linked to Ransomware

The threat landscape report from BGD e-GOV CIRT shows a significant 71.39% increase in malware infections linked to potential ransomware threats.

“Forces Penpals” exposed US and UK Military Social Network’s 1 Million Records

Renowned cybersecurity researcher Jeremiah Fowler uncovered a non-password-protected database having over 1.1 million records linked to Conduitor Limited (Forces Penpals)....
Read More
“Forces Penpals” exposed US and UK Military Social Network’s 1 Million Records

CVE-2024-51503
Trend Micro released updates for Deep Security Agent RCE

Trend Micro released a security update for Deep Security 20 Agent Manual Scan Command Injection RCE Vulnerability (CVE-2024-51503) that resolves...
Read More
CVE-2024-51503  Trend Micro released updates for Deep Security Agent RCE

Apple Releases Patch for two Actively Exploited Zero-Day

Apple released critical updates for its various products including for iOS, iPadOS, macOS, visionOS, and Safari to fix two zero-day...
Read More
Apple Releases Patch for two Actively Exploited Zero-Day

Maxar Space Data Leak, Company admit, Investigation ongoing!

Maxar Space Systems has verified a major data breach that exposed particular information of current and former workers. The breach...
Read More
Maxar Space Data Leak, Company admit, Investigation ongoing!

GitHub CLI Vulnerability Could Allow RCE

A security vulnerability (CVE-2024-52308) in the GitHub Command Line Interface (CLI) could allow remote code execution on users' devices. With...
Read More
GitHub CLI Vulnerability Could Allow RCE

“Sarcoma” ransomware group
Hacker to disclose “Popular Life Insurance” 36 GB of stolen data

“Sarcoma” ransomware group attacked a well known Bangladeshi insurance company named "Popular life insurance company ltd". The threat actor keeps...
Read More
“Sarcoma” ransomware group  Hacker to disclose “Popular Life Insurance” 36 GB of stolen data

BugHunt 2024: A Milestone Cyber security Competition held at Dhaka

Bug Hunt 2024, one of the largest cyber security competitions and conferences in Bangladesh, was successfully held at the ICT...
Read More
BugHunt 2024: A Milestone Cyber security Competition held at Dhaka

TP-Link DHCP Vulnerability Allow Attackers Takeover Routers Remotely

A serious security flaw has been found in some TP-Link routers, potentially enabling hackers to remotely access the affected devices.The...
Read More
TP-Link DHCP Vulnerability Allow Attackers Takeover Routers Remotely

WSJ reports
T-Mobile hacked in massive breach of telecom networks

The Wall Street Journal reported on Friday citing people familiar with the matter that T-Mobile’s network was among the systems...
Read More
WSJ reports  T-Mobile hacked in massive breach of telecom networks

Palo Alto Networks Confirms critical RCE zero-day actively exploited

"Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall...
Read More
Palo Alto Networks Confirms critical RCE zero-day actively exploited

The report shows that there exist vulnerabilities in Bangladesh that could lead to ransomware attacks on various organizations. The main malware strains identified are M0yv, Phorpiex, and Necurs, which can trigger different types of ransomware attacks such as Maze, Avaddon, Grandcab, and Locky.

CIRT found many attempts related to Indicators of Compromise (IOCs) of Mallox Ransomware. These attempts focused mainly on exploiting weaknesses in Mysql or Microsoft SQL services.

The report shows a global statistics where Bangladesh has been shown at the top hit list by ransomware Trojans than any other country:

Source: BGD e-GOV CIRT

CIRT found four major ransomware incidents in 2023, including one by LockBit 3.0 targeting a top pharmaceutical company in Bangladesh. The hackers claimed to have accessed 750GB of data, including personal files of key employees, infrastructure, and accounting data.

In March 2023, a major ransomware attack occurred in Bangladesh, targeting a prominent transportation organization. The attacker, known as “Money Message,” was new to the ransomware criminal activity. The affected company’s critical server and some computers were attacked by ransomware from Money Message, causing disruption to operations. Attacker demanded a large ransom to give back access to the server and said they’d release 100GB of personal data they got into.

            Source: Bleeping computer

ALPHV claimed they were responsible for hacking a financial organization in Bangladesh. They were able to access 170 GB of sensitive data, including SQL backups, financial data, employee information, and more. They also claimed to have implanted a backdoor to maintain ongoing access to the network.

On June, the Akira ransomware group targeted and attacked a large company in Bangladesh. They claimed responsibility for the attack and listed the company as a victim on their website. The group stated that the company’s leadership refused to negotiate the ransom amount, so they released the company’s leaked data on their dark website.

Malware variants related to ransomware:

The CTI Unit of BGD e-GOV CIRT found different versions of ransomware threats. In the last year, they discovered 25,038 unique cases of IP addresses from Bangladesh affected by these malware infections.

Source: BGD e-GOV CIRT

The indicators of compromise are connected to ransomware threat actors, which raises concerns about ransomware attacks on the affected networks. In 2023, there has been a significant 71.39% increase in malware infections compared to 2022, all associated with potential ransomware risks.

Active ransomware strains:

BGD e-GOV CIRT is working to identify possible ransomware activities. Its main objective is to provide useful information to protect important information systems and organizations.

In 2023, CTI unit found traces of 7 different ransomware threats. It’s important to note that none of these threats were able to infiltrate or compromise any infrastructure. However, CIRT observed active attempts from these ransomware actors. The graphic below shows these active attempts by ransomware entities:

Source: BGD e-GOV CIRT

CIRT have noticed a significant increase in brute force attacks by well-known ransomware groups targeting Bangladeshi domains. Its analysis has identified traces possibly linked to the Mallox ransomware group.

This discovery is very important because it matches the warnings given by many cybersecurity companies in July of last year. They reported a huge 174% increase in Mallox ransomware activities compared to the previous year.

The Mallox group is known for attacking unsecured MS-SQL servers to get into a network. They start by trying a list of common passwords to break in, and once they’re in, they use a command line and PowerShell to download the Mallox ransomware from a remote server. Additionally, we’ve also noticed active attempts to break into  etworks by other well-known ransomware threats like Blackbasta, Medusa, Emotet Lockbit 3, Blackcat, and Play.

Check Also

T mobile

WSJ reports
T-Mobile hacked in massive breach of telecom networks

The Wall Street Journal reported on Friday citing people familiar with the matter that T-Mobile’s …

Leave a Reply

Your email address will not be published. Required fields are marked *